sk83520 - How to verify that Security Gateway and/or Security Management Server can access Check Point servers?

How to verify that Security Gateway and/or Security Management Server can access Check Point servers?

Solution

Security Gateways and Security Management Server require access to the Internet (either directly, or via configured proxy) for various Software Blades.

Important Notes:

If you disabled the default Implied Rules, then you must follow sk179346 - Configuring Explicit Rules instead of Implied Rules.

Notes:

Notes:

For more information about Updatable objects, see sk131852.

The table below lists the relevant connectivity tests.

Enter the string to filter this table:

Hostname Protocol From Used For (Version) Verifying Connectivity (Run command listed below. You will get a response if connectivity is OK.)
cws.checkpoint.com http Security Gateway,
Security Management Server,
SMB Gateways
Social Media Widget Detection curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/APPI/SystemStatus/type/short
URL Filtering Cloud Categorization curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/URLF/SystemStatus/type/short
Virus Detection curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/AntiVirus/SystemStatus/type/short
Bot Detection curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/Malware/SystemStatus/type/short
updates.checkpoint.com https
http
Security Gateway,
Security Management Server,
Spark Firewall
IPS Updates,
Updatable Object (R80.20 and higher, on Security Gateway and Security Management)
curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://updates.checkpoint.com/WebService/Monitor
crl.godaddy.com https
http
Security Gateway,
Security Management Server
Update Service uses it for revocation curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://crl.godaddy.com/
crl.globalsign.com http Security Gateway,
Security Management Server
CRL that updates service certificate uses curl_cli -v http://crl.globalsign.com/
dl3.checkpoint.com https Security Gateway,
Security Management Server
Download Service Updates
Updatable Object (R80.20 and higher, on Security Gateway and Security Management)
curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://dl3.checkpoint.com
usercenter.checkpoint.com https Security Gateway,
Security Management Server
Contract Entitlement for IPS, Traditional Anti-Virus, Legacy URL Filtering curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://usercenter.checkpoint.com/usercenter/services/productcoverageservice
usercenter.checkpoint.com https Security Gateway,
Security Management Server
Software Blades Manager Service curl_cli [--proxy <IP_or_HostName:Port>] -v --cacert $CPDIR/conf/ca-bundle.crt https://usercenter.checkpoint.com/usercenter/services/BladesManagerService
resolver1.chkp.ctmail.com
resolver2.chkp.ctmail.com
resolver3.chkp.ctmail.com
resolver4.chkp.ctmail.com
resolver5.chkp.ctmail.com
http Security Gateway Suspicious Mail Outbreaks curl_cli [--proxy <IP_or_HostName:Port>] -v http://resolver1.chkp.ctmail.com
download.ctmail.com http Security Gateway,
Security Management Server
Anti-Spam curl_cli [--proxy <IP_or_HostName:Port>] -v http://download.ctmail.com
te.checkpoint.com https Security Gateway Threat Emulation curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://te.checkpoint.com/tecloud/Ping
teadv.checkpoint.com https
http
Security Gateway Threat Emulation curl_cli [--proxy <IP_or_HostName:Port>] -v http://teadv.checkpoint.com/version.txt
threat-emulation.checkpoint.com https Security Gateway Threat Emulation curl_cli [--proxy <IP_or_HostName:Port>] -v https://threat-emulation.checkpoint.com/tecloud/Ping
ptcs.checkpoint.com
ptcd.checkpoint.com
https Security Gateway Private ThreatCloud (PTC) Updates curl_cli [--proxy <IP_or_HostName:Port>] -v https://ptcs.checkpoint.com
curl_cli [--proxy <IP_or_HostName:Port>] -v https://ptcd.checkpoint.com
kav8.zonealarm.com http Security Gateway Archive scanning,
Deep inspection
curl_cli [--proxy <IP_or_HostName:Port>] -v http://kav8.zonealarm.com/version.txt
kav8.checkpoint.com https
http
Security Gateway
Endpoint Security Management
Traditional Anti-Virus,
Endpoint Security Management pulling Anti-Malware updates
curl_cli [--proxy <IP_or_HostName:Port>] -v http://kav8.checkpoint.com/version.txt
avupdates.checkpoint.com https
http
Security Gateway Traditional Anti-Virus,
Legacy URL Filtering
curl_cli [--proxy <IP_or_HostName:Port>] -v http://avupdates.checkpoint.com/UrlList.txt
sigcheck.checkpoint.com http Security Gateway,
Security Management Server
Download of signature updates for Traditional Anti-Virus, Legacy URL Filtering, UTM-1 Edge devices curl_cli [--proxy <IP_or_HostName:Port>] -v http://sigcheck.checkpoint.com/Siglist2.txt
secureupdates.checkpoint.com http General updates server for Check Point gateways Manage Security Gateways curl_cli [--proxy <IP_or_HostName:Port>] -I http://secureupdates.checkpoint.com/IP-list/100k.txt
productcoverage.checkpoint.com https Security Gateway,
Security Management Server
Makes sure the contracts are up-to-date curl_cli [--proxy <IP_or_HostName:Port>] -v https://productcoverage.checkpoint.com/productcoverageservice
sc1.checkpoint.com
sc2.checkpoint.com
sc3.checkpoint.com
sc4.checkpoint.com
sc5.checkpoint.com
https Security Gateway,
Security Management Server,
SmartConsole,
SmartDashboard
Download of icons and screenshots from Check Point media storage servers (e.g., Check Point AppWiki) curl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/sc/images/checkmark.gif
curl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/za/images/facetime/large_png/60342479_lrg.png
curl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/za/images/facetime/large_png/60096017_lrg.png
push.checkpoint.com https Mobile Access Gateway Push Notifications for incoming e-mails and meeting requests on handheld devices, while the Capsule Workspace Mail app is in the background curl [--proxy <IP_or_HostName:Port>] -v -k https://push.checkpoint.com/push/ping
downloads.checkpoint.com http Mobile Access Gateway,
Security Management Server
Download of Endpoint Compliance Updates (Endpoint Security On Demand (ESOD) database):
curl_cli [--proxy <IP_or_HostName:Port>] -v http://downloads.checkpoint.com
productservices.checkpoint.com https Security Gateway,
Security Management Server
Next Generation Licensing (Entitlement / Licensing Updates) curl_cli [--proxy <IP_or_HostName:Port>] -v http://productservices.checkpoint.com
diag-services.checkpoint.com https Security Gateway,
Security Management Server
Core Dump File uploader (Authentication / Upload backend) curl [--proxy <IP_or_HostName:Port>] -v -k https://diag-services.checkpoint.com
mercury.ts.checkpoint.com
fairfax.ott.checkpoint.com
ftp-proxy.checkpoint.com
https Security Gateway,
Security Management Server
File uploader for CPinfo, CP_Uploader, CPSizeMe (to a server in USA, Canada, Israel) curl [--proxy <IP_or_HostName:Port>] -v -k mercury.ts.checkpoint.com
curl [--proxy <IP_or_HostName:Port>] -v -k fairfax.ott.checkpoint.com
curl [--proxy <IP_or_HostName:Port>] -v -k ftp-proxy.checkpoint.com
rep.checkpoint.com https Security Gateway,
Security Management Server, Cloud Firewall agents for Kubernetes workloads
Reputation service curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://rep.checkpoint.com -X POST -w '\nHTTP Status: %{http_code}\n'
<Service-Identifier>.maas.checkpoint.com https Smart-1 Cloud service On-premises Management Server and On-premises Security Gateways connect to the Smart-1 Cloud service To test connectivity with Smart-1 Cloud deployments in Europe:
curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw.portal.checkpoint.com
To test connectivity with Smart-1 Cloud deployments in the United States:
curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw-us.portal.checkpoint.com
To test connectivity with Smart-1 Cloud deployments in the APAC:
curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw.ap.portal.checkpoint.com
api-cpx.dome9.com
api.dome9.com
api-cpx.eu1.dome9.com
api.eu1.dome9.com
api-cpx.ap2.dome9.com
api.ap2.dome9.com
api-cpx.cace1.dome9.com
api.cace1.dome9.com
api-cpx.ap3.dome9.com
api.ap3.dome9.com
api-cpx.ap1.dome9.com
api.ap1.dome9.com
https Cloud Firewall agents for Kubernetes workloads Cloud Firewall services curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://api-cpx.dome9.com/namespaces -X POST
curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://api.dome9.com -X POST -w '\nHTTP Status: %{http_code}\n' -o /dev/null
shiftleft.portal.checkpoint.com
shiftleft-prod-bucket.sg.iaas.checkpoint.com
us-gw.sg.iaas.checkpoint.com
eu-gw.sg.iaas.checkpoint.com
au-gw.sg.iaas.checkpoint.com
ca-gw.sg.iaas.checkpoint.com
in-gw.sg.iaas.checkpoint.com
sg-gw.sg.iaas.checkpoint.com
https Cloud Firewall agents for Kubernetes workloads Vulnerability scanner services curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://shiftleft.portal.checkpoint.com
*.amazontrust.com
ocsp.e2m02.amazontrust.com
ocsp.e2m03.amazontrust.com
ocsp.e2m04.amazontrust.com
crt.e2m02.amazontrust.com
crt.e2m03.amazontrust.com
crt.e2m04.amazontrust.com
crl.e2m02.amazontrust.com
crl.e2m03.amazontrust.com
crl.e2m04.amazontrust.com
ocsp.rootca1.amazontrust.com
ocsp.rootca2.amazontrust.com
ocsp.rootca3.amazontrust.com
ocsp.rootca4.amazontrust.com
ocsp.rootg2.amazontrust.com
crt.rootca1.amazontrust.com
crt.rootca2.amazontrust.com
crt.rootca3.amazontrust.com
crt.rootca4.amazontrust.com
crt.rootg2.amazontrust.com
crl.rootca1.amazontrust.com
crl.rootca2.amazontrust.com
crl.rootca3.amazontrust.com
crl.rootca4.amazontrust.com
crl.rootg2.amazontrust.com
http Security Gateway,
Security Management Server
Services in Check Point Portal (formerly, Infinity Portal) curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>
dns.google.com icmp Spark Firewall Probing 1. In WebUI, go to "Device" view > "System" section > "Tools" page.
2. Use the Ping tool.
dns.cloudflare.com icmp Spark Firewall Probing 1. In WebUI, go to "Device" view > "System" section > "Tools" page.
2. Use the Ping tool.
dns.opendns.com icmp Spark Firewall Probing 1. In WebUI, go to "Device" view > "System" section > "Tools" page.
2. Use the Ping tool.
smbcloud-api-gateway.iaas.checkpoint.com https Spark Firewall Spark Firewall cloud services curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://smbcloud-api-gateway.iaas.checkpoint.com/health
*.spark-management.checkpoint.com https Spark Firewall Spark Management - Spark Firewall activation curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>
*.spark-management.checkpoint.com http Spark Firewall CRL check curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>
*.portal.checkpoint.com
*.in.portal.checkpoint.com
https Spark Firewall Services in Check Point Portal (formerly, Infinity Portal) curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>
*.iaas.checkpoint.com https Spark Firewall Spark Firewall activation service curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>
*.<Region>.ddnsbox.com TCP port 53 Spark Firewall Dynamic DNS (DDNS) curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN>
zerotouch.checkpoint.com https Spark Firewall Zero Touch deployment test zero-touch-request
smbmgmtservice.checkpoint.com https Spark Firewall SMP Portal deployment - obsoleted by Spark Management smp_connectivity_test smbmgmtservice.checkpoint.com
See sk179105.
Note - These domains are part of the " Check Point Services" Updatable object.
https Check Point Portal (formerly, Infinity Portal) Services in Check Point Portal (formerly, Infinity Portal) curl_cli [--proxy <IP_or_HostName:Port>] -v -k <URL>

Additional Notes:

Show / Hide Examples from R7X SmartDashboard

Note: Check if you have one those blades enabled and configure proxy settings for each of them.

  1. Go to the "Mobile Access" tab
    1. Expand the "Endpoint Security On Demand"
    2. Click on the "Endpoint Compliance Updates"
    3. In the "Automatic Update" section, click on the "Configure..." button
    4. Go to the "Proxy" tab

Example:

  1. Go to the "Application & URL Filtering" tab
    1. Expand the "Legacy URL Filtering"
    2. Click on the "Legacy URL Filtering Policy"
    3. Click on the "Automatic updates" link
    4. Go to the "Proxy" tab

Example:

  1. Go to the "Threat Prevention" tab
    1. Expand the "Traditional Anti-Virus"
    2. Click on the "Database Updates"
    3. In the "Automatic Update" section, click on the "Configure..." button
    4. Go to the "Proxy" tab

Example:

Revision History

Date Description
18 May 2025 Added servers for CPinfo, CP_Uploader, CPSizeMe
10 Jan 2025 Added the notes about Access Control policy and NAT policy
23 Oct 2024 Added .maas.checkpoint.com
14 Apr 2024 Updated the list for Spark Firewall
01 Nov 2023 - Added reference to Proxy configuration in the applicable Administration Guides
- Added Check Point Portal services (sk179105)
29 May 2017 Added information about Proxy configuration on top of the Proxy global property configured in the object of Security Management Server / Domain Management Server
25 Apr 2017 Added http://downloads.checkpoint.com
16 Feb 2017 Added "Revision History" section
02 Mar 2017 Added teadv.checkpoint.com